Level 1: MINAF-PC7, 650 / 650 (100%)
100% complete
Level 2: Alert! Emergency!, 750 / 750 (100%)
100% complete
Level 3: We're not happy, 400 / 725 (55%)
55.172413793103% complete
Total: 1,800 / 2,125 (84.7%)
Challenge Solved Points
3.7 From which REAL domain was this last attack launched? (Level 3: We're not happy) #39, 4 years, 3 months after release (2026-03-04 16:42:22) 75
3.5 The attackers are nice tricksters because they also fooled this user. Which URL did they make him/her click? (Level 3: We're not happy) #29, 4 years, 3 months after release (2026-03-04 16:36:37) 100
3.4 The compromised initial user has been connecting from another countries ... Which one is the most frequent? (Level 3: We're not happy) #44, 4 years, 3 months after release (2026-03-04 16:12:10) 50
3.3 This kind of attack is EXACTLY called ... (Level 3: We're not happy) #41, 4 years, 3 months after release (2026-03-04 16:00:39) 100
3.2 Who fooled this user to install the "thingy" ? (Level 3: We're not happy) #46, 4 years, 3 months after release (2026-03-04 16:00:15) 75
2.7 Attackers have left a privileged backdoor to MINAF's O365. Which form does it take? (Level 2: Alert! Emergency!) #43, 4 years, 3 months after release (2026-03-04 15:54:10) 125
2.6 To expand their activities, the attackers have obtained full access to some mailboxes. Which ones? (Level 2: Alert! Emergency!) #42, 4 years, 3 months after release (2026-03-04 15:52:26) 75
2.9 Which in the "innocent" password of the compromised account ? (Level 2: Alert! Emergency!) #45, 4 years, 3 months after release (2026-03-04 15:49:37) 100
2.8 When the attackers did first successfully use the stolen account ? (Level 2: Alert! Emergency!) #45, 4 years, 3 months after release (2026-03-04 15:33:24) 75
2.5 Attackers also created an email rule that filtered out some keywords. Which ones? (Level 2: Alert! Emergency!) #42, 4 years, 3 months after release (2026-03-04 15:18:45) 75
2.4 The attackes have given themselves permissions over two Sharepoint sites. Who are their owners? (Level 2: Alert! Emergency!) #43, 4 years, 3 months after release (2026-03-04 15:08:53) 75
2.3 ... and from which IP address? (Level 2: Alert! Emergency!) #43, 4 years, 3 months after release (2026-03-04 14:57:18) 50
2.2. When did the attackers got the World_Happiness_Plan.docx? (Level 2: Alert! Emergency!) #44, 4 years, 3 months after release (2026-03-04 14:56:58) 100
2.1 María José Feliz shared this file with an user ... who reshared it with a third user. Who? (Level 2: Alert! Emergency!) #49, 4 years, 3 months after release (2026-03-04 14:34:41) 75
1.9 María José Feliz shared this document with other user. Which one? (Level 1: MINAF-PC7) #54, 4 years, 3 months after release (2026-03-04 14:18:39) 75
1.8 How many times have been the compressed payload successfully executed? (Level 1: MINAF-PC7) #40, 4 years, 3 months after release (2026-03-04 12:48:31) 100
1.7 Which user advises Maria Jose Files to "install" everything? (Level 1: MINAF-PC7) #65, 4 years, 3 months after release (2026-03-04 12:33:37) 125
1.6 Where did all these malware was downloaded from? (Level 1: MINAF-PC7) #65, 4 years, 3 months after release (2026-03-04 11:56:46) 75
1.4 Which payload do these files have? (Level 1: MINAF-PC7) #63, 4 years, 3 months after release (2026-03-04 11:45:00) 75
1.5 In that folder there is DEFINITELY another file that Windows Defender strongly dislikes. Which one? (Level 1: MINAF-PC7) #65, 4 years, 3 months after release (2026-03-04 11:40:38) 50
1.3 If you look carefully in the user folder, you'll see some suspicious compressed files. What final (real) extension is the most used? (Level 1: MINAF-PC7) #76, 4 years, 3 months after release (2026-03-04 11:26:46) 50
1.2 Which file generated the most recent AV alert? (Level 1: MINAF-PC7) #74, 4 years, 3 months after release (2026-03-04 11:21:57) 50
1.1 At which time did María José Feliz create the document "World_Happiness_Plan.docx" on her computer? (Level 1: MINAF-PC7) #66, 4 years, 3 months after release (2026-03-04 11:15:51) 50